CVE-2009-3923: High severity sun virtual desktop infrastructure vulnerability
The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote attackers to obtain unspecified access via vectors involving requests to an Apache HTTP Server.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3923?
CVE-2009-3923 is classified as a critical vulnerability due to its potential for unauthorized access without authentication.
How do I fix CVE-2009-3923?
To fix CVE-2009-3923, ensure that authentication is enabled for the web service in VirtualBox and Sun Virtual Desktop Infrastructure.
What systems are affected by CVE-2009-3923?
CVE-2009-3923 affects Oracle VM VirtualBox versions 2.0.8 and 2.0.10, as well as Sun Virtual Desktop Infrastructure version 3.0.
Can CVE-2009-3923 be exploited remotely?
Yes, CVE-2009-3923 can be exploited remotely by attackers to gain unauthorized access.
Is there a workaround for CVE-2009-3923?
A potential workaround for CVE-2009-3923 is to restrict access to the web service using firewall rules until a proper patch is applied.